- Sources: report, discussion
- Summary: Patrick Wardle of the Objective-See Foundation found that any local app or code can change an undocumented Muse setting controlling the transcription endpoint, so pointing it at an attacker-run server hands over the account token. Muse holds WhatsApp, email, calendar, and purchase authority, and the reported delivery path is a ClickFix-style single command run by the user. Ars Technica reported that more than 12 hours after publication Meta said it had released a hotfix, and that Amazon began blocking Muse from its site and asked Meta to remove Amazon from the experience. Ars gives no affected or fixed Muse version numbers.
- Why it matters: A single ClickFix-style command could take over an agent holding WhatsApp, email, calendar, and purchase authority on macOS.
- Follow-up: Track whether Meta narrows the account token scope for Muse and whether it explains routing transcription through the cloud.
send feedback on this story